Our Blog
CGNAT was an emergency fix. We made it the default, and it neutered the Internet.
How carrier-grade NAT conserved IPv4 addresses, made direct connections harder and changed what peers and builders can do online.

The internet didn't downgrade by accident. I watched it happen.
I've spent my whole career inside this network. I mapped it with the Opte Project. I defended it at Prolexic when botnets were trying to knock half of e-commerce offline. I've written tools that tunnel TCP over DNS and over CDNs just to prove packets can still find a way. So when I tell you the internet quietly traded away its founding principle, I'm not theorizing. I was in the room.
The trade happened one rational decision at a time. Make things connect. Conserve scarce resources. Keep the old world running one more year. Every one of those decisions made sense. Then we made the temporary ones permanent.
Carrier-Grade NAT (CGNAT) is the clearest example. It stretched the final years of IPv4, and in doing so, it turned the internet from a network of reachable peers into a world of clients, clouds, relays, and middlemen. It wasn't a conspiracy. It was worse than a conspiracy: it was a technically rational shortcut that got institutionalized because everyone in the room could make it work. An entire industry decided it was easier to preserve IPv4 than to preserve the end-to-end internet.
I grew up on direct internet
The original internet ran on one powerful idea: endpoints reach endpoints. If you had a routable address, another host could connect straight to you. You could run a server from your bedroom. Host a game. Move a file to a friend without asking permission. You didn't need five SaaS vendors, a CDN, a relay service, and a venture-backed platform standing between two people who wanted to talk.
The network moved packets. It didn't need to understand your business model. It didn't need to be your identity provider. It didn't need to become a permanent middleman.
It was messy. It was also glorious. Then IPv4 ran out.
The emergency
IPv4 is a 32-bit address space of about 4.3 billion addresses. That sounded infinite until every human started carrying three connected devices and every company put its infrastructure online.
NAT was the first workaround: a whole house sharing one public address. CGNAT took the same trick to the carrier level by putting thousands of customers behind a small pool of public addresses, with the standards bodies carving out 100.64.0.0/10 as dedicated shared space to make it official.
I want to be fair here, because I've operated networks under real constraints: CGNAT was a reasonable emergency response. Providers had IPv4-only devices to serve, IPv6 was half-deployed, and IPv4 addresses were getting absurdly expensive. They needed to connect the next customer.
But "emergency" is supposed to mean temporary. Instead, we built the world on top of the tourniquet.
What we actually gave up
CGNAT demoted you from participant to guest.
Your phone, your laptop, your home network: the address they hold may not be reachable from the public internet at all. Your traffic gets translated by carrier-owned equipment before it goes anywhere. If your home router is already doing NAT, you're behind two layers: one you own, one you don't.
Try hosting a service from home. Try receiving an inbound connection. Try running a multiplayer game, a camera, a peer-to-peer app, or remote access without a third party in the middle. Sometimes it works, after a ridiculous dance of port mappings, hole punching, relay servers, subscriptions, and support tickets. I've written some of those workarounds myself. The fact that they need to exist is the indictment.
And when direct connectivity gets hard, centralization gets easy. You stop sending the file to your friend; you upload it to a cloud. You stop hosting; you rent. Builders stop building on the network and start building on the intermediaries who can route around it. Every layer of translation is a dependency, every dependency is a chokepoint, and every chokepoint is a place where connectivity can fail, policy can be imposed, traffic can be observed, or access can be sold back to you.
The internet got easier to control as it got harder to reach.
Privacy didn't get a free pass either
CGNAT isn't a surveillance product. But it is a structural correlation point. When thousands of subscribers share one public address, the carrier has to map internal addresses, ports, and timestamps just to make the system function. More translation means more infrastructure sitting between you and the internet, more places where your activity can be associated, logged, and inspected.
The privacy industry has spent a decade patching this from above. Add a VPN. Add a browser extension. Add encrypted DNS. Add another proxy. Some of it helps. But if the architecture underneath is still built on intermediaries, you're mostly choosing which intermediary gets the best view of your life. That's not privacy. That's outsourcing trust.
We kept the workaround and canceled the repair
IPv6 was the actual fix. It offers address space vast enough to make every endpoint reachable again. The CGNAT standards were explicitly framed as a bridge to it. But bridges have a way of becoming destinations. CGNAT relieved the pressure, providers kept adding customers, and the migration everyone promised became the migration nobody prioritized.
Today, direct reachability isn't normal. It's a premium feature you buy, configure, or hack around.
What comes next must leverage IPv6 and circumvent CGNAT
I'm not nostalgic for 1998, and you shouldn't be either. We need modern cryptography, real resilience, serious abuse protection, and we're about to need all of it at a scale nobody's honest about, because billions of AI agents are about to become the heaviest users of every network on earth. Those agents are inheriting an internet built for billing, reachability workarounds, and observation, not autonomy, not privacy, not direct control. If we keep treating duct tape as architecture, we'll automate the same failures at machine speed.
The next internet has to assume that endpoints can talk without defaulting to someone else's relay. That your identity and your activity don't automatically land in the same database. That naming and trust don't require kneeling before a handful of public intermediaries. That security kills threats in the network instead of generating alerts after the damage. That people, and their agents, run on infrastructure designed to minimize surveillance, not monetize it.
Come build with us
I got tired of writing essays about it, so I'm building the fabric instead. It's called doxx.net: our own autonomous system, our own naming, an encrypted mesh where endpoints are endpoints again: reachable, private, and yours.
If any of this resonates and, if you remember what it felt like when the network was actually yours, come see what we're building at doxx.net. Kick the tires, put some traffic on it, and tell me what you think.
